[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2024-28085Date: (C)2024-03-29   (M)2024-04-26


wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover.

Reference:
https://lists.debian.org/debian-lts-announce/2024/04/msg00005.html
https://github.com/skyler-ferrante/CVE-2024-28085
https://github.com/util-linux/util-linux/security/advisories/GHSA-xv2h-c6ww-mrjq
https://mirrors.edge.kernel.org/pub/linux/utils/util-linux/
https://people.rit.edu/sjf5462/6831711781/wall_2_27_2024.txt
https://www.openwall.com/lists/oss-security/2024/03/27/5

OVAL    8
oval:org.secpod.oval:def:613032
oval:org.secpod.oval:def:708858
oval:org.secpod.oval:def:708869
oval:org.secpod.oval:def:89051709
...
XCCDF    1

© SecPod Technologies